Drooid Logo
Back to story perspectives

Full Breakdown

Data Exposure Raises Concerns Over AI Toy Manufacturer Miko's Privacy Practices

2/13/2026, 2:34:38 AM

Overview of the Data Exposure Incident

Senators Marsha Blackburn (R-Tenn.) and Richard Blumenthal (D-Conn.) have raised alarms regarding a significant data exposure involving Miko, a manufacturer of AI-powered toys. Their investigation revealed that Miko had left an unsecured database accessible to the public, which contained thousands of audio responses from the toys to children. This database reportedly included identifiable information, such as children's names and details of their conversations with the toys, prompting concerns about the company's commitment to data privacy.

Details of the Exposed Database

The unsecured database, which was viewed by NBC News, contained audio files organized in folders labeled “GOOGLE” and “AZURE,” referring to cloud computing services. These folders included subfolders for various languages, indicating a wide range of interactions. The audio files dated back to December 2025 and were categorized by specific dates, allowing for the tracking of individual conversations. Although the children's voice recordings were not present, the responses provided insights into their interactions with the toys, raising privacy concerns.

Miko's Response to Allegations

In response to the senators' concerns, Miko CEO Sneh Vaswani stated that there had been no breach or leak of user data. He emphasized that Miko does not store children's voice recordings and asserted that no personal information was made publicly accessible. Vaswani indicated that the company is preparing a detailed response to the senators' inquiries regarding the data exposure.

Expert Opinions on Privacy Risks

Privacy advocates have expressed serious concerns about the implications of this incident. Miranda Bogen, director of the Center for Democracy and Technology’s AI Governance Lab, criticized the lack of security measures, stating that failing to secure interactions with AI systems reflects a disregard for privacy and security. R.J. Cross, a campaign director at the U.S. Public Interest Research Group, echoed these sentiments, emphasizing that parents have the right to question the company's ability to protect sensitive data.

Broader Implications and Future Actions

Following the exposure, Senators Blackburn and Blumenthal reached out to other AI toy manufacturers, including Curio and FoloToy, seeking information on their data security practices. The senators inquired about parental control mechanisms and the companies' commitments to safeguarding children's data. Curio responded by affirming its dedication to transparency and compliance with applicable laws, while FoloToy had not yet provided a response.

Conclusion: The Need for Vigilance

This incident highlights the vulnerabilities associated with AI-powered children's products and underscores the necessity for parents to remain vigilant regarding data protection practices. As the debate over privacy standards in the AI toy industry continues, it is crucial for manufacturers to prioritize the security of children's data and engage in meaningful dialogue with policymakers and stakeholders.